Rapid7 Vulnerability & Exploit Database

RHSA-2005:504: telnet security update

Back to Search

RHSA-2005:504: telnet security update

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
06/14/2005
Created
07/25/2018
Added
10/28/2005
Modified
07/12/2017

Description

Updated telnet packages that fix an information disclosure issue are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team.

The telnet package provides a command line telnet client. Gael Delalleau discovered an information disclosure issue in the way the telnet client handles messages from a server. An attacker could construct a malicious telnet server that collects information from the environment of any victim who connects to it. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0488 to this issue. Users of telnet should upgrade to this updated package, which contains a backported patch to correct this issue.

Solution(s)

  • redhat-upgrade-telnet
  • redhat-upgrade-telnet-server

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;